{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T18:35:38Z","timestamp":1781548538213,"version":"3.54.5"},"reference-count":95,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3404258","type":"journal-article","created":{"date-parts":[[2024,5,22]],"date-time":"2024-05-22T17:34:22Z","timestamp":1716399262000},"page":"5767-5782","source":"Crossref","is-referenced-by-count":8,"title":["CMXsafe: A Proxy Layer for Securing Internet-of-Things Communications"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7738-5517","authenticated-orcid":false,"given":"Jorge David","family":"de Hoz Diego","sequence":"first","affiliation":[{"name":"Computer, Electrical and Mathematical Science and Engineering Division, King Abdullah University of Science and Technology, Thuwal, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Taous","family":"Madi","sequence":"additional","affiliation":[{"name":"Computer, Electrical and Mathematical Science and Engineering Division, King Abdullah University of Science and Technology, Thuwal, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3825-3930","authenticated-orcid":false,"given":"Charalambos","family":"Konstantinou","sequence":"additional","affiliation":[{"name":"Computer, Electrical and Mathematical Science and Engineering Division, King Abdullah University of Science and Technology, Thuwal, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Ericsson Mobility Report","author":"Baur et al","year":"2022"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3059457"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3079916"},{"key":"ref4","volume-title":"Luabot: Malware targeting cable modems","author":"Rodrigues","year":"2016"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00013"},{"key":"ref6","first-page":"1","article-title":"Towards an architecture for trusted edge IoT security gateways","volume-title":"Proc. 3rd USENIX Workshop Hot Topics Edge Comput. (HotEdge)","author":"McCormack"},{"key":"ref7","volume-title":"2H State of XIoT Security 2022","year":"2022"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.201"},{"key":"ref9","volume-title":"Azure Industrial IoT Platform","year":"2023"},{"key":"ref10","volume-title":"AWS IoT Device SDK C. SDK for Connecting To AWS IoT From a Device Using Embedded C. Migration Guide for MQTT","year":"2020"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487830"},{"key":"ref12","first-page":"799","article-title":"The secure socket API: TLS as an operating system service","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"ONeill"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/diss.2018.23007"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3232755.3232774"},{"key":"ref15","first-page":"4187","article-title":"Capture: Centralized library management for heterogeneous IoT devices","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Zhang"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3224649"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2900939"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/s42979-019-0018-8"},{"key":"ref19","volume-title":"Overview of Azure Hub Device Provisioning Service","author":"Azure","year":"2022"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3096062"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICUFN57995.2023.10199497"},{"key":"ref22","volume-title":"The ISTIO Service Mesh","year":"2021"},{"key":"ref23","volume-title":"Linkerd: The World Lightest and Fastest Service Mesh","year":"2023"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19849-6_31"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2907793"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3065123"},{"key":"ref27","volume-title":"Briefing: EU Cyber-Resilience Act","author":"Car","year":"2023"},{"key":"ref28","volume-title":"Why Device Authentication is Necessary for the IoT","year":"2023"},{"key":"ref29","first-page":"1133","article-title":"Discovering and understanding the security hazards in the interactions between IoT devices, mobile apps, and clouds on smart home platforms","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Zhou"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3201557"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-76736-5_30"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3063806"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3037908"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.iswa.2022.200106"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3379542"},{"issue":"2","key":"ref36","doi-asserted-by":"crossref","first-page":"567","DOI":"10.3390\/s22020567","article-title":"Preventing MQTT vulnerabilities using IoT-enabled intrusion detection system","volume":"22","author":"Husnain","year":"2022","journal-title":"Sensors"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SOSE55356.2022.00027"},{"key":"ref38","first-page":"1183","article-title":"Shattered chain of trust: Understanding security risks in cross-cloud IoT access delegation","volume-title":"Proc. 29th USENIX Security Symp. (USENIX Secur.)","author":"Yuan"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3338843"},{"key":"ref40","volume-title":"Configuring Mutual TLS Authentication for a REST API\u2014Amazon API Gateway","year":"2023"},{"key":"ref41","first-page":"1","article-title":"ALPACA: Application layer protocol confusion-analyzing and mitigating cracks in TLS authentication","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Brinkmann"},{"key":"ref42","volume-title":"Hackers Exploiting Abandoned Boa Web Servers To Target Critical Industries","author":"Lakshmanan","year":"2024"},{"key":"ref43","volume-title":"Industrial Wireless IoT\u2014The Direct Path to Your Level 0"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2916553"},{"key":"ref45","first-page":"233","article-title":"Open to a fault: On the passive compromise of TLS keys via transient errors","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Sullivan"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3497762"},{"key":"ref47","doi-asserted-by":"crossref","DOI":"10.17487\/RFC9325","volume-title":"Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)","author":"Sheffer","year":"2022"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103028"},{"issue":"13","key":"ref49","doi-asserted-by":"crossref","first-page":"5004","DOI":"10.3390\/s22135004","article-title":"Improving security of web servers in critical IoT systems through self-monitoring of vulnerabilities","volume":"22","author":"Song","year":"2022","journal-title":"Sensors"},{"key":"ref50","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-030-63086-7_9","article-title":"MisMesh: Security issues and challenges in service meshes","volume-title":"Security and Privacy in Communication Networks","author":"Hahn","year":"2020"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103119"},{"key":"ref52","volume-title":"The SSH Connection Protocol: TCP\/IP Port Forwarding","author":"Lonvick","year":"2006"},{"key":"ref53","volume-title":"WolfSSH Lightweight SSH Library","year":"2022"},{"key":"ref54","volume-title":"Azure RTOS ThreadX Modules Documentation. Chapter 1: Overview","year":"2023"},{"key":"ref55","volume-title":"IoT & Edge Developer Survey Report","year":"2023"},{"key":"ref56","volume-title":"OpenSSH Portable Release","year":"2023"},{"key":"ref57","volume-title":"Mosquitto: An Open-source MQTT Broker","year":"2022"},{"key":"ref58","doi-asserted-by":"crossref","DOI":"10.17487\/RFC8138","volume-title":"IPv6 Over Low-Power Wireless Personal Area Network (6LoWPAN) Routing Header","author":"Thubert","year":"2017"},{"key":"ref59","volume-title":"The SSH Connection Protocol: Channel Mechanisms","author":"Lonvick","year":"2006"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2951306"},{"key":"ref61","volume-title":"Dropbear SSH","author":"Johnston","year":"2022"},{"key":"ref62","volume-title":"Terminology for Constrained-Node Networks","author":"Bormann","year":"2024"},{"key":"ref63","volume-title":"BusyBox: The Swiss Army Knife of Embedded Linux","author":"Vlasenko et al","year":"2023"},{"key":"ref64","volume-title":"WolfSSH Adds Support for Zephyr RTOS","year":"2024"},{"key":"ref65","volume-title":"Cybersecurity labeling for Internet of Things","year":"2023"},{"key":"ref66","volume-title":"National Cybersecurity Strategy","author":"DOD","year":"2023"},{"key":"ref67","volume-title":"Regulation of the European Parliament and the Council on Horizontal Cybersecurity Requirements for Products With Digital Elements and Amending Regulation (EU) 2019\/1020","year":"2022"},{"key":"ref68","volume-title":"Security Evaluation Standard for Iot Platforms (SESIP)"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2017.8170867"},{"key":"ref70","first-page":"1169","article-title":"All things considered: An analysis of IoT devices on home networks","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Kumar"},{"key":"ref71","doi-asserted-by":"crossref","DOI":"10.17487\/rfc1928","volume-title":"SOCKS Protocol Version 5","author":"Leech","year":"1996"},{"key":"ref72","volume-title":"OpenVPN `Enforce Zero Trust Access: Never Trust, Always Verify","year":"2024"},{"key":"ref73","first-page":"5719","article-title":"Bypassing tunnels: Leaking VPN client traffic by abusing routing tables","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Xue"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/InCIT56086.2022.10067674"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/CCGridW59191.2023.00017"},{"key":"ref76","volume-title":"Multiprotocol Label Switching Architecture","author":"Viswanathan","year":"2001"},{"issue":"2021","key":"ref77","first-page":"26633","article-title":"Executive order 14028: Improving the nations cybersecurity","volume":"86","author":"Biden","year":"2021","journal-title":"Daily J. United States Goverment"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-207"},{"key":"ref79","volume-title":"Zero Trust Maturity Model","year":"2023"},{"issue":"13","key":"ref80","doi-asserted-by":"crossref","first-page":"2763","DOI":"10.3390\/app9132763","article-title":"VPNFilter malware analysis on cyber threat in smart home network","volume":"9","author":"Sapalo Sicato","year":"2019","journal-title":"Appl. Sci."},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-023-1456-2"},{"key":"ref82","volume-title":"OBM Memorandum M-22-09: Moving the U.S. Government Toward Zero Trust Cybersecurity Principles","year":"2022"},{"key":"ref83","volume-title":"DoD Zero Trust Reference Architecture","year":"2023"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3056650"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2018.8423017"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/3301305"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1145\/2834050.2834095"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516655"},{"key":"ref89","first-page":"609","article-title":"TrustBase: An architecture to repair and strengthen certificate-based authentication","volume-title":"Proc. 26th USENIX Security Symp. (USENIX Secur.)","author":"ONeill"},{"key":"ref90","volume-title":"OpenSSL Changelog","year":"2021"},{"key":"ref91","volume-title":"QUIC-based UDP Transport for Secure Shell (SSH)","author":"Bider","year":"2021"},{"key":"ref92","volume-title":"Secure Shell Over HTTP\/3 Connections","author":"Michel","year":"2024"},{"key":"ref93","volume-title":"SSH3: Faster and Rich Secure Shell Using HTTP\/3","author":"Michel","year":"2024"},{"key":"ref94","article-title":"Towards SSH3: how HTTP\/3 improves secure shells","author":"Michel","year":"2023","journal-title":"arXiv:2312.08396"},{"key":"ref95","volume-title":"A QUIC Implementation in Pure Go","author":"Seemann","year":"2024"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/10319981\/10536903.pdf?arnumber=10536903","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,30]],"date-time":"2024-05-30T05:41:05Z","timestamp":1717047665000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10536903\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":95,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3404258","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}